CVE-2024-7348 PUBLISHED CVSS 8.800000190734863 HIGH

A ‘time-of-check time-of-use’ (TOCTOU) race condition in a PostgreSQL can allow an attacker to easily execute arbitrary SQL functions by leveraging a PostgreSQL utility often executed with high privileges.

EPSS 0.76% · 73.3th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
EPSS Score
0.76%
73.3th percentile

Affected Products

VendorProductVersions
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4 SP1
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU1
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4 SP2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU3

Timeline

References

Open in Interactive Console →